{79} Survey Methodology Bulletin May 2019 Contents Preface The methodological challenges of Stephanie 1 protecting outputs from a Flexible Blanchard Dissemination System An investigation into using data Gareth L. 16 science techniques for the Jones processing of the Living Costs and Foods survey Distributive Trade Transformation: Jennifer 28 Methodological Review and Davies Recommendations Forthcoming Courses, 46 Methodology Advisory Service and GSS Methodology Series The Survey Methodology Bulletin is primarily produced to inform staff in the Office for National Statistics (ONS) and the wider Government Statistical Service (GSS) about ONS survey methodology work. It is produced by ONS, and ONS staff are encouraged to write short articles about methodological projects or issues of general interest. Articles in the bulletin are not professionally refereed, as this would considerably increase the time and effort to produce the bulletin; they are working papers and should be viewed as such. The bulletin is published twice a year and is available as a download only from the ONS website. The mission of ONS is to improve understanding of life in the United Kingdom and enable informed decisions through trusted, relevant, and independent statistics and analysis. On 1 April 2008, under the legislative requirements of the 2007 Statistics and Registration Service Act, ONS became the executive office of the UK Statistics Authority. The Authority's objective is to promote and safeguard the production and publication of official statistics that serve the public good and, in doing so, will promote and safeguard (1) the quality of official statistics, (2) good practice in relation to official statistics, and (3) the comprehensiveness of official statistics. The National Statistician is the principal advisor on these matters. www.ons.gov.uk Edited by: Philip Lowthian [email protected] SMB79 i Stephanie Blanchard The methodological challenges of protecting outputs from a Flexible Dissemination System The methodological challenges of protecting outputs from a Flexible Dissemination System Stephanie Blanchard 1 1. Introduction There is increasing demand on National Statistical Institutions from users for more data to be made publicly available and released sooner after collection. There is also a greater desire by the Office for National Statistics (ONS) to make better use of the data that is held. A solution to satisfy both sides is to look at new and innovative ways to disseminate data. A project currently underway at ONS is the development of a Flexible Dissemination System (FDS) for the 2021 Census which has produced a ‘proof of concept’ prototype; the result of collaboration between the Statistical Disclosure Control (SDC) team in Methodology, the 2021 Census Outputs team, Digital Publishing and an external company. Further work will be to investigate the potential of using an FDS beyond the release of Census data. The core aims of the project are to address user feedback for more flexible, accessible and timely outputs but these user requirements have to be balanced against the requirements for the ONS to protect the data. This has identified a number of methodological challenges to protecting data accessed through an FDS which are described, along with potential solutions, in this paper. 2. A Flexible Dissemination System for outputs Traditionally, a data output comprises of a series of static tables which once released, cannot be changed. The aim is to design the tables to meet the majority of user needs while maintaining data confidentiality, a vital requirement for all data outputs as described in section 3. If users require an additional table to those published, in some cases a commissioned table service is provided by the data holder, usually with a charge to the customer, which can involve a lengthy negotiation process to agree a table that is acceptable to the user while meeting confidentiality requirements. Rather than provides a series of tables, an FDS provides an online interface where users can define their own tables by building a query from a list of selections provided by the data holder which could include the level of geography, the table population and the variables. The table is built in real time from the unit record level microdata which is held securely and not accessible by the user. Confidentiality is maintained through the disclosure control methods applied to the microdata and algorithms applied to the table once built, before it is released to the user. 1 Office for National Statistics [email protected] SMB79 1 Stephanie Blanchard The methodological challenges of protecting outputs from a Flexible Dissemination System Figure 1: Flow of processes through a Flexible Dissemination System Data holder’s secure server User defined query Safe table released Disclosive SDC Microdata Table applied Geography Population Variables 2.1. Benefits of a Flexible Dissemination System There are two main benefits of an FDS; flexibility and timeliness. In an FDS, users can define their own tables based on their individual requirements and priorities. The level of flexibility will depend on the options made available through the FDS but it is likely to lead to more data being made available to the user, either through more detailed versions of tables that had previously been released or through combinations of variables that weren’t previously made available. Offering more flexibility to users could reduce the demand on a commission table service as users will be able to get more through the FDS, but the service may still be required for tables of non-standard construction as technical capability may limit the functionality of the FDS. Outputs will be available sooner through an FDS as time is saved by not having to design the tables, build and disclosure check them. The shorter lead time for producing outputs is achieved by applying automated SDC methods although there is an initial time and resource investment by the data holder to design the content of the FDS and define the parameters of the automated SDC methods. For data releases that comprise a large number of tables released in stages, time gains can also be made by applying automated SDC methods since all the data can be released together. 2.2. Application of a Flexible Dissemination System The biggest benefits in flexibility and timeliness will be where there is a large number of tables generated from a single data source which has a wide user base with different priorities and requirements. An example of this is the UK Census. Following the 2011 Census, ONS published over 5,000 standard release tables for England and Wales based on 650 table templates covering a variety of geographies. There have also been a further 900 commission tables released and that number is still growing even seven years after census day. Census data are accessed by a large variety of users including Local Authorities, academics, charities, businesses and enquiring citizens. Following Census day, it took around 16 months for ONS to publish the first outputs and a further 2 years and 8 months until the last outputs were published. The reason for this long time lapse was down to the table building process which included designing the tables based on users’ requirements, manual checking for disclosures by the SDC team, table re-design when disclosures were identified and finally building the table for publication. User feedback after the 2011 Census was that they generally liked the SDC SMB79 2 Stephanie Blanchard The methodological challenges of protecting outputs from a Flexible Dissemination System methods used, since it allowed small counts to be produced unlike the 2001 Census methods, but they were disappointed that no significant gains had been made regarding flexibility and timeliness. Based on this feedback, work started in 2015 on the development of an FDS. This will provide the 2021 Census outputs with both flexibility and timeliness; the aim being to publish the first outputs within 12 months of census day and for all outputs to be released within 24 months. National Records of Scotland (NRS) and the Northern Ireland Statistics and Research Agency (NISRA) are also developing FDSs for disseminating their 2021 Census outputs. ONS, NRS and NISRA are aiming for harmonisation in the dissemination approaches for the 2021 Census wherever possible. 3. What Statistical Disclosure Control is and why we need it SDC is the application of methods to protect respondents in statistical outputs. A respondent could be an individual, a household, a business or any other statistical unit. A statistical output can take many forms including microdata datasets, frequency tables, magnitude tables, graphs and visualisations. The principle behind many SDC methods is to introduce sufficient uncertainty into the outputs such that a respondent cannot be identified or their characteristics revealed to an intruder, an intruder being someone who either purposefully tries to identify a respondent or someone who inadvertently stumbles upon a respondent through using the data or output. There are many examples in the literature on disclosure risk and methods, including Hundepool et al (2012). Determining the most appropriate SDC method(s) for an output is/are based on a range of factors with the ultimate aim of maintaining a satisfactory relationship between disclosure risk and data utility. In order to make an output safe for release, the disclosive data must be changed in some way to protect the outputs. This will damage the utility of the data so it essential to select the disclosure control methods that will reduce the disclosure risk to an acceptable level while maximising the data utility in line with user requirements. Application of disclosure control is required because ONS has legal obligations under the Statistics and Registration Service Act (2007)2 and the General Data Protection Regulation (2018)3. If a breach occurred it could result in action being taken against the organisation as well as the individuals involved including fines and criminal proceedings.
Details
-
File Typepdf
-
Upload Time-
-
Content LanguagesEnglish
-
Upload UserAnonymous/Not logged-in
-
File Pages50 Page
-
File Size-